Logfile of Kaka v2. 0. 0. 9 Scan Module v2. 0. 0. 1
Scan saved at 14:07:28, on 2006-10-06
Platform: Microsoft Windows XP Professional Service Pack 2 (Build 2600)
MSIE: Internet Explorer v6.00 SP2; (6.00.2900.2180 (xpsp_sp2_rtm.040803-2158))
Running processes:
[smss.exe]
CommandLine =
[csrss.exe]
CommandLine = C:\WINDOWS\system32\csrss.exe
ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[winlogon.exe]
CommandLine = winlogon.exe
[services.exe]
CommandLine = C:\WINDOWS\system32\services.exe
[lsass.exe]
CommandLine = C:\WINDOWS\system32\lsass.exe
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k DcomLaunch
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost -k rpcss
[CCenter.exe]
CommandLine = "E:\Rising\Rav\CCenter.exe"
[svchost.exe]
CommandLine = C:\WINDOWS\System32\svchost.exe -k netsvcs
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k NetworkService
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k LocalService
[RavMonD.exe]
CommandLine = "E:\Rising\Rav\Ravmond.exe"
[explorer.exe]
CommandLine = C:\WINDOWS\Explorer.EXE
[spoolsv.exe]
CommandLine = C:\WINDOWS\system32\spoolsv.exe
[RavStub.exe]
CommandLine = E:\Rising\Rav\RavStub.exe /RAVMOND
[svchost.exe]
CommandLine = C:\WINDOWS\system32\svchost.exe -k imgsvc
[wdfmgr.exe]
CommandLine = C:\WINDOWS\system32\wdfmgr.exe
[SOUNDMAN.EXE]
CommandLine = "C:\WINDOWS\SOUNDMAN.EXE"
[RavTask.exe]
CommandLine = "E:\RISING\RAV\RAVTASK.EXE" -SYSTEM
[RavMon.exe]
CommandLine = "E:\Rising\Rav\Ravmon.exe" -SYSTEM
[QQ.exe]
CommandLine = "F:\Tencent\QQ.exe"
[TIMPlatfrom.exe]
CommandLine = F:\Tencent\TIMPlatfrom.exe
[alg.exe]
CommandLine = C:\WINDOWS\System32\alg.exe
[taskmgr.exe]
CommandLine = taskmgr.exe
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
[IEXPLORE.EXE]
CommandLine = "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
[KkScan.exe]
CommandLine = "E:\Rising\KkScan.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.baidu.com/
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RavTask] "E:\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\RunOnce: [RavStub] "E:\Rising\Rav\ravstub.exe" /RUNONCE
O4 - Startup: 腾讯QQ.lnk = F:\Tencent\QQ.exe
O8 - Extra context menu item: 上传到QQ网络硬盘 - F:\Tencent\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - F:\Tencent\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - F:\Tencent\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - F:\Tencent\SendMMS.htm
O16 - DPF: {A96C48EA-AA88-4BBD-B58C-7B41146A6EAC} (Qzone Media Tools) - http://qz-photo.qq.com/qzone3/QzoneMediaTools.cab
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O23 - Service: Human Interface Device Access (HidServ) - - C:\WINDOWS\system32\svchost.exe -k netsvcs
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - "E:\Rising\Rav\CCenter.exe"
O23 - Service: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - "E:\Rising\Rav\Ravmond.exe"